Skip to content

docs: install Homebrew casks by fully qualified name - #2409

Merged
gtrrz-victor merged 2 commits into
mainfrom
soph/homebrew-install-one-liner
Sep 15, 2026
Merged

gtrrz-victor merged 2 commits into
mainfrom
soph/homebrew-install-one-liner

Conversation

@Soph

@Soph Soph commented Sep 14, 2026 •

Copy link
Copy Markdown
Collaborator

https://entire.io/gh/entireio/cli/trails/1323

brew tap entireio/tap fails under Homebrew 6's tap trust, so the documented install died on step one. A fully qualified cask name auto-taps without that audit and grants itself scoped trust, collapsing the flow to one command.

Also adds a stable-install job to the nightly smoke workflow. Its macOS leg only covered nightly, and the old sequence there ran brew trust before brew tap — the working order — so CI stayed green while the README was broken.

Verified end to end on a clean machine. Needs Homebrew 6.0.10+, which is where Homebrew/brew#23027 fixed the conflicts_with blocker that held up #1427.

Closes #2394. Supersedes #1427, which proposed the same fix first.

🤖 Generated with Claude Code


Note

Low Risk
Documentation and CI-only changes to install commands; no runtime CLI or auth/data-path changes.

Overview
Homebrew installs are documented and exercised as a single fully-qualified cask (entireio/tap/entire / entire@nightly) instead of separate brew tap, brew trust, and short cask names. The README explains that Homebrew 6’s tap-trust rules make the old flow fail on step one, and that qualified names auto-tap with scoped trust (Homebrew 6.0.10+).

Nightly install smoke aligns macOS nightly setup with that one-liner. A new stable-install job on macos-latest runs the documented stable install only (no checkout/E2E): it asserts the tap appeared without an explicit brew tap, both entire and git-remote-entire are on PATH, and entire version is not a nightly build. Scheduled Slack alerts now fire if either smoke or stable-install fails, with copy that covers install failures on any channel/OS.

Reviewed by Cursor Bugbot for commit 62ca8a5. Configure here.

`brew tap entireio/tap` fails outright under Homebrew 6's tap trust: tapping
runs a readall audit over every cask in the tap, each load hits the trust check,
and the tap is left empty behind `Cannot tap entireio/tap: invalid syntax in
tap!`. The README told users to run it first, so the documented install died on
step one (#2394).

A fully qualified `<tap>/<token>` is exempt from that check, and `brew install`
auto-taps without the audit (`Tap#install` defaults to `verify: false`; only
`cmd/tap.rb` passes `verify: true`), then persists scoped trust for the one cask
it installed. So the whole flow collapses to a single command, with `brew
upgrade` still working by short name afterwards.

This is what #1427 proposed. It was held back because `conflicts_with` then
forced you to trust both casks before either would install; Homebrew fixed that
in 6.0.10 (Homebrew/brew#23027) by rescuing UntrustedTapError in
`check_conflicts`. The other two mechanisms predate tap trust entirely, so
6.0.10 is the floor.

Also add a stable-install job to the nightly smoke workflow. The macOS leg only
ever installed the nightly cask, and the old sequence there ran `brew trust`
before `brew tap` — the working order — so CI stayed green while the README was
broken. A runner starts with no tap and no trust entries, which is the state
that reproduces it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Entire-Checkpoint: 01M2FQ0T9HKP0D66WSXARC39PC
@Soph
Soph requested a review from a team as a code owner September 14, 2026 10:29
Copilot AI lite review requested due to automatic review settings September 14, 2026 10:29

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Make the Slack alert heading channel-neutral or identify the failing installation job.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Updates Homebrew installation documentation and CI smoke coverage for Homebrew 6 tap trust.

Changes:

  • Uses fully qualified stable and nightly cask names.
  • Adds stable installation smoke testing.
  • Expands Slack failure notifications to both install jobs.
File summaries
File Description Review finding
README.md Documents fully qualified Homebrew cask installs. No findings.
.github/workflows/nightly-e2e.yml Updates nightly installation and adds stable validation. Alert heading should identify stable-only failures accurately.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/nightly-e2e.yml Outdated
The heading was unambiguous while the workflow tested one channel: the
schedule, the workflow and the release channel were all "nightly". Covering
stable split those, so a stable-only failure alerted "Nightly install smoke
failed" while the nightly job had passed.

The body already reads "a published CLI ... at least one channel/OS", so the
heading was the only part asserting a channel. Naming the failing job instead
would need three nested ternaries inside the JSON payload to cover both-failed;
the run link already carries it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Entire-Checkpoint: 01M2FRRTCT6J0EPT4EHBF7MTKV
@gtrrz-victor
gtrrz-victor merged commit 78bc44b into main Sep 15, 2026
19 of 21 checks passed
@gtrrz-victor
gtrrz-victor deleted the soph/homebrew-install-one-liner branch September 15, 2026 13:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

Documentation triest to tap before trusting which is not allowed in Homebrew 6

3 participants